Risk assessment

Cybersecurity Risk Assessment

Information Security, Data Protection and Cyber Resilience for an Online / Virtual Clinic

For Telehealth & Online ClinicRef BS-TEL-RA-002See a sample (PDF) →
£44.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This risk assessment is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Scope and purpose
  • 2. Legal and regulatory framework
  • 3. Risk assessment methodology
  • 4. Hazards, controls and risk rating
  • 5. Action plan
  • 6. Monitoring and review
  • 7. Disclaimer

Legislation & standards it maps to

  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 12 (Safe care and treatment), Regulation 13 (Safeguarding service users from abuse and improper treatment) and Regulation 17 (Good governance)
  • UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • The Network and Information Systems Regulations 2018 (the NIS Regulations)
  • Computer Misuse Act 1990
  • Data (Use and Access) Act 2025
  • The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • The Caldicott Principles (2020) and the common law duty of confidentiality
  • The Data Security and Protection Toolkit (DSPT) and the National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) - aligned standards

Who it applies to

All clinical, clinical-support, administrative, IT, information-governance and contractor personnel of [Organisation Name] who access, process, store or transmit patient or business information through online consultation platforms, electronic patient records, prescribing systems, websites, mobile applications and connected devices.

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

AES-256
A strong, widely used method of scrambling stored data so that only authorised people can read it.
Artificial-intelligence-assisted triage
Using computer software that mimics human judgement to help sort or prioritise patients before a clinician sees them.
Audit log
An automatic record of who accessed or changed information and when, used to detect and investigate misuse.
Bring-your-own-device (BYOD)
An arrangement that lets staff use their own personal phones, tablets or computers for work.
Business continuity plan
A plan setting out how a service will keep running, or quickly recover, when something disrupts it.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information.
Caldicott Principles
A set of nationally agreed rules for handling confidential patient information safely and appropriately.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Cloud-hosted
Software and data run on remote internet servers managed by a provider, rather than on computers in your own building.
Common law duty of confidentiality
A long-standing legal duty to keep information that someone shares in confidence private unless there is a proper reason to disclose it.
Computer Misuse Act 1990
The law that makes it a criminal offence to access or damage computer systems without permission.
Conditional access
A security rule that only allows a sign-in if certain conditions are met, such as the device being approved and up to date.
Controlled drug
A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
Cookies
Small files a website stores on a visitor's device to remember them or track how the site is used.
CREST-accredited
Carried out by a security tester certified by CREST, an internationally recognised body for the cybersecurity testing industry.
Cyber Assessment Framework (CAF)
A national framework for checking how well an organisation manages cyber risks to important services.
Cyber Essentials Plus
A government-backed certification, with independent testing, showing an organisation has basic cybersecurity protections in place.
Data (Use and Access) Act 2025
A United Kingdom law that updates the rules on using and sharing data, including health and care information.
Data Protection Act 2018
The United Kingdom law that sits alongside the UK GDPR and governs how personal information must be handled.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The person responsible for advising an organisation on data-protection law and monitoring that it is followed.
Data processing agreement
A written contract that sets out how a supplier handling personal data on your behalf must protect it.
Data residency
The physical country or region where an organisation's data is stored.
Data Security and Protection Toolkit (DSPT)
An online self-assessment that health and care organisations use to show they handle data and cybersecurity safely.
Data subject
The living individual that a piece of personal information is about.
Denial of service (DoS / DDoS)
An attack that floods a website or system with traffic so that genuine users cannot use it.
DKIM
An email security check that adds a digital signature so the recipient can confirm a message genuinely came from your organisation.
DMARC
An email security policy that tells receiving servers what to do with messages that fail anti-spoofing checks, helping to stop fraud.
Electronic patient record (EPR)
A patient's medical record held in a computer system rather than on paper.
Electronic Prescription Service (EPS)
A national service that sends prescriptions electronically from the prescriber to a pharmacy.
Encryption
Scrambling information so that only someone with the correct key can read it.
Endpoint detection and response (EDR)
Security software on computers and devices that spots, investigates and helps stop attacks.
End-to-end encryption
Protection that scrambles a message or call so that only the people communicating can read or hear it, and no one in between.
European Economic Area (EEA)
The European Union countries plus Iceland, Liechtenstein and Norway, treated as a single area for data-protection purposes.
Fundamental standards
The minimum standards of safety and quality below which care must never fall.
GP Connect
A national service that lets authorised health and care systems securely view and share information held in general-practice records.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting out the fundamental standards that providers of regulated care must meet.
HTTPS / HSTS
HTTPS encrypts the connection between a browser and a website; HSTS (HTTP Strict Transport Security) forces that secure connection to always be used.
Immutable backup
A backup copy that cannot be altered or deleted for a set period, so it survives a ransomware attack.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Information Commissioner's Office (ICO)
The United Kingdom regulator responsible for upholding data-protection and information rights.
ISO 27001
An internationally recognised standard for managing information security within an organisation.
Joiners-movers-leavers (JML)
The process for granting, changing and removing someone's system access as they join, change role in, or leave an organisation.
Least privilege
Giving each person only the access they actually need to do their job, and no more.
Mobile device management (MDM)
Software that lets an organisation secure, control and, if needed, remotely wipe the phones, tablets and laptops used for work.
Multi-factor authentication (MFA)
Signing in with more than one proof of identity, such as a password plus a code or fingerprint, for stronger security.
National Cyber Security Centre (NCSC)
The United Kingdom's national authority providing advice and support on cybersecurity.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Network and Information Systems Regulations 2018 (NIS Regulations)
The law setting cybersecurity and incident-reporting duties for operators of essential services and certain digital service providers.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Passkey / FIDO2
A modern, password-free way of signing in that is highly resistant to phishing, using a security key or a device's built-in security.
Patch management
Keeping software and systems updated with the fixes that close security weaknesses.
Penetration testing
Authorised, simulated hacking of a system to find security weaknesses before real attackers do.
Personal Demographics Service
A national electronic database of patient contact and demographic details used across health and care services.
Phishing
Fraudulent emails or messages designed to trick people into revealing passwords or other sensitive information.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The law covering electronic marketing, cookies and the privacy of electronic communications.
Ransomware
Malicious software that locks or encrypts an organisation's data and demands payment to release it.
Record of Processing Activities (ROPA)
A documented inventory of the personal data an organisation holds and how and why it is used.
Recovery-point objective (RPO)
The maximum amount of data, measured in time, that an organisation can afford to lose in an outage.
Recovery-time objective (RTO)
The maximum acceptable length of time a system can be down before it must be restored.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Residual risk
The level of risk that remains after existing controls and safeguards have been taken into account.
Risk assessment
A structured check identifying what could cause harm and what is being done to prevent it.
Role-based access control
Granting access to systems according to a person's job role, so they only see what that role requires.
Safeguarding
Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
Senior Information Risk Owner (SIRO)
The senior person accountable for managing information risk across an organisation.
Service-level agreement (SLA)
A contract setting out the standard of service, such as availability or response time, that a supplier must provide.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Smartcard
A secure plastic card with a chip used, with a passcode, to prove identity and access clinical systems such as electronic prescribing.
Social engineering
Manipulating people through deception into giving away information or access they should not.
Special category data
Particularly sensitive personal data, such as information about a person's health, that the law gives extra protection.
SPF
An email security check that lists which servers are allowed to send email for your organisation, helping to block forged messages.
Spine
The central national computer system that securely connects health and care services and their patient information.
SQL injection
An attack that inserts malicious database commands through a website to steal or damage data.
Standard operating procedure (SOP)
A written step-by-step instruction for carrying out a routine task consistently and safely.
Sub-processor
A further supplier that a data processor uses to help handle personal data on an organisation's behalf.
TLS (Transport Layer Security)
A standard that encrypts information as it travels across the internet to keep it private and unaltered.
UK General Data Protection Regulation (UK GDPR)
The United Kingdom's main data-protection law governing how personal information is collected and used.
Virtual private network (VPN)
A secure, encrypted connection over the internet that protects data travelling between a user and a network.
Vulnerability scanning
Automated checking of systems for known security weaknesses so they can be fixed.
Web application firewall (WAF)
A protective filter that screens incoming web traffic and blocks common attacks against a website or application.
Zero-trust access
A security approach that verifies every user and device on each request rather than trusting anything by default.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyTelehealth Consent Policy£54.99
PolicyCybersecurity Policy£54.99
PolicyRemote Assessment Policy£54.99
PolicyData Protection Policy£54.99

Need the whole set?

Buy the full Telehealth & Online Clinic pack and save versus buying documents individually.

View the Telehealth & Online Clinic pack